Virtual appliance packaging and out-of-the-box intelligence allows for a fast, easy, and cost-effective SIEM deployment, with a remarkable time to value. Sentinel’s packaging also enables you to quickly ramp up deployment to handle growth and increase capacity as your security needs change.
Sentinel can leverage ArcSight’s industry-leading SmartConnectors, which collect, normalize, and enrich data from 450+ data source types to help ensure enterprise-wide threat visibility. Sentinel also offers a big data (Hadoop) backend to scalably collect and reliably store large amounts of data with ease, and in a way that can quickly adapt to shifting business needs.
Sentinel Log Manager enables the collection, storage, analysis, and management of security logs to proactively manage risk and address compliance reporting needs. It offers a cost-effective 10:1 compression ratio and flexible data storage options. It also comes with intuitive searching and filtering, distributed search capabilities, and intelligent one-click reporting.
Most SIEMs require time-consuming rule-writing and configuration, but not Sentinel Enterprise. It ships with packaged intelligence to address the core needs of SIEM right out of the box and leverages anomaly detection to support its security monitoring. Its graphical, drag-and-drop interface enables rapid correlation rule-building without significant training or experience.
Sentinel delivers the industry's only seamless integration between SIEM and IAM. Through its out-of- the-box integration with NetIQ Identity Manager and Change Guardian, Sentinel can add significant context to the “who, what, when, and where” of user activities and events across your environment. This valuable identity intelligence enables automated anomaly detection, as well as greater awareness of risky behaviors and insider threats.